HIPAA Security

HIPAA Security


February 17, 2017 | Reading Time: 2 Minutes

Please support Telehealth.org’s ability to deliver helpful news, opinions, and analyses by turning off your ad blocker. How

Easy Steps for HIPAA Security

Understanding HIPAA security standards is essential to maintaining compliance in your practice. HIPAA regulation mandates that covered entities, such as physicians, insurance companies, and health care clearinghouses, implement a compliance program that addresses these security standards to protect patient health data.

When it comes to HIPAA security, there are three major components that you need to address within your practice in order to keep protected health information (PHI) secure. PHI includes sensitive patient health data such as names, dates of birth, social security numbers, and medical records.

Below, we discuss the basic elements of HIPAA security so you can understand how a total HIPAA compliance program can help protect your behavioral health practice from data breaches and fines.

Physical Security

Physical HIPAA security is important because it involves protecting your office or physical location. Any PHI that is stored in paper form must be sufficiently protected. That means that health records must be kept in a secure location such as a locked filing cabinet or locked room. Only authorized employees should be able to access these records as a part of the work they’ve been hired to do for you.

Additionally, physical security requirements extend to overall site access. Entrances and exits must be secured and locked to prevent break-ins and unlawful entries to the site.

Technological Security

Technological HIPAA security is essential to protecting electronic PHI (ePHI). All devices that can access, store, handle, or maintain ePHI must be inventoried regularly. These devices must be properly secured with high-security passwords, with added full-disc encryption for extra protection.

Additionally, networks must be protected from malware and cyber-attacks. Depending on the scope of your behavioral health practice, you may need to implement a firewall to safeguard patient information from unlawful access.

Administrative Security

Administrative HIPAA security involves tracking and documenting your security polices and procedures. You must have written documentation of the steps you’ve taken to address security requirements. In the event that your behavioral health practice experiences a data breach or HIPAA fine, you must be able to present investigators with this documentation.

It’s essential to keep this information updated regularly to ensure that ongoing HIPAA security measures are being maintained.

Essential Telehealth Law & Ethical Issues

Bring your telehealth practice into legal compliance. Get up to date on inter-jurisdictional practice, privacy, HIPAA, referrals, risk management, duty to warn, the duty to report, termination, and much more!

Disclaimer: Telehealth.org offers information as educational material designed to inform you of issues, products, or services potentially of interest. We cannot and do not accept liability for your decisions regarding any information offered. Please conduct your due diligence before taking action. Also, the views and opinions expressed are not intended to malign any organization, company, or individual. Product names, logos, brands, and other trademarks or images are the property of their respective trademark holders. There is no affiliation, sponsorship, or partnership suggested by using these brands unless contained in an ad. Some of Telehealth.org’s blog content is generated with the assistance of ChatGPT. We do not and cannot offer legal, ethical, billing technical, medical, or therapeutic advice. Use of this site constitutes your agreement to Telehealth.org Privacy Policy and Terms and Conditions.

Please share your thoughts in the comment box below.

Notify of
Inline Feedbacks
View all comments

Register for Free

Receive Any of Our 57 FREE Newsletters!


Most Popular Blog Topics

You May Also Like…

ChatGPT HIPAA Considerations
ChatGPT HIPAA Considerations

ChatGPT HIPAA compliance is one of the hottest topics at 2023 conferences and with good reason. AI...